- Joined
- Jun 21, 2022
- Messages
- 4
- Reaction score
- 1
Hi all,
briefly about us we are a system house and run about 40 3CX-phonesystems at our customers with different installations. ( Windows / Linux / Cloud )
In 5 systems, we had in recent weeks various external calls to foreign numbers ( eg countries in Africa / etc. ) from different extensions.
Currently we have done the following:
- disabled complete console access from external
- changed extension passwords
- changed 3CX tunnel password
- changed root passwords / admin passwords on operating system
- changed backup passwords
According to 3CX support the admin passwords were lost, but we think this is unlikely as it happened to 5 customers almost at the same time.
The passwords were all automatically generated and had at least 20 characters. In our documentation they are protected by MFA and are stored in Keepass databases.
Has anyone had similar experiences ?
Could the admin passwords have been lost before the last security update and are only now being exploited ? ( the security updates were installed promptly )
Many greetings
Translated with www.DeepL.com/Translator (free version)
briefly about us we are a system house and run about 40 3CX-phonesystems at our customers with different installations. ( Windows / Linux / Cloud )
In 5 systems, we had in recent weeks various external calls to foreign numbers ( eg countries in Africa / etc. ) from different extensions.
Currently we have done the following:
- disabled complete console access from external
- changed extension passwords
- changed 3CX tunnel password
- changed root passwords / admin passwords on operating system
- changed backup passwords
According to 3CX support the admin passwords were lost, but we think this is unlikely as it happened to 5 customers almost at the same time.
The passwords were all automatically generated and had at least 20 characters. In our documentation they are protected by MFA and are stored in Keepass databases.
Has anyone had similar experiences ?
Could the admin passwords have been lost before the last security update and are only now being exploited ? ( the security updates were installed promptly )
Many greetings
Translated with www.DeepL.com/Translator (free version)
